CVE-2020-2242: Jenkins Database

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.

Affected products

  • Jenkins Database: up to and including 1.6

Published 2020-09-01. Last modified 2026-06-17.